Skip to content

Collegeville, Pennsylvania · Serving Greater Philadelphia

Digital forensics for litigation and corporate investigations

4n6PI collects, preserves, and examines digital evidence for attorneys, corporate legal teams, and companies. Every matter is handled by the examiner who signs the report.

Evidence is not found. It is preserved, or it is lost.

A phone syncs overnight. Logs rotate. IT reimages the laptop before anyone thinks to ask. By the time a matter is filed, the record that would have answered the question is frequently gone already, and no amount of skill recovers what has been overwritten.

What survives is a matter of procedure. Devices are acquired write-blocked, so nothing on the original changes. Every image is hash-verified at acquisition and again at delivery, so the copy can be proven identical to the source. Custody is signed at the moment of handoff rather than reconstructed afterward, so the signature and the event share one clock. Each device is treated as its own record, and a finding from one is never carried to another.

The work is performed by certified examiners and documented so that another examiner, working independently from the same source, would reach the same result. That is the standard the rules of evidence rest on, and it is what separates a finding that holds from one that merely sounds right.

Reports state what the evidence supports, and say plainly where it stops.

Services

What 4n6PI does

For legal and litigation

Forensic Collection & Preservation

Defensible acquisition of computers, mobile devices, and removable media. Write-blocked imaging, hash verification, and chain of custody documented from intake through delivery.

Learn more

Computer Forensics

Examination of laptops, desktops, and servers. File access and transfer history, USB and cloud activity, deleted content, and reconstruction of what a user actually did and when.

Learn more

Mobile Device Forensics

iOS and Android acquisition and analysis. Messages, call records, application data, location history, and deleted content, delivered in a form your team can review.

Learn more

Independent Forensic Review

Review of forensic reports, extractions, and conclusions produced by another party. Whether the methodology was sound, and whether the source data actually supports what was claimed.

Learn more

eDiscovery & Forensic Collection

Microsoft 365, Purview, and cloud account collection. Legal hold administration, custodian collection, and export packaging formatted for your review platform.

Learn more

For enterprise

Endpoint Investigations & Incident Response

Forensic investigation of compromised endpoints and active incidents. Triage, scope determination, timeline reconstruction, and reporting, working alongside your response lead.

Learn more

Insider Threat & Data Theft

Investigation of exfiltration, policy violation, and separation matters. What left, when it left, where it went, and what evidence supports each of those answers.

Learn more

EnCase Deployment & Recovery

Deploy, upgrade, troubleshoot, and recover EnCase Endpoint Investigator environments, including SAFE and node communication failures and post-upgrade recovery.

Learn more

Microsoft Purview & Defender Support

Purview eDiscovery workflow, legal hold configuration, and Defender threat hunting inside your existing tenant. Built by someone who has stood the program up at enterprise scale.

Learn more

Pricing

Collection and analysis are priced separately

Most firms quote a single number that bundles acquisition and investigation together, so you commit to the analysis before anyone knows whether the matter needs it. 4n6PI separates the two.

ServiceRateWhat it covers
Mobile device acquisition and processing$2,500Flat, per single device
Hard drive imaging$1,500Flat, per single drive
Investigation and analysis$150/hrOnly when the matter calls for it
Storage mediaAt costNo markup

What the flat rate includes

Forensic acquisition, hash verification, chain of custody documentation, and output formatted for review. You can take that output and search it yourself, or engage 4n6PI to perform the investigation at the hourly rate. Where a matter needs one, a review platform is provided.

Multi-device matters are quoted per engagement. Travel and on-site work is billed at cost with advance written authorization.

Location

Based in Montgomery County, not a landing page

4n6PI works out of Collegeville, Pennsylvania. Devices are collected in person across Norristown, King of Prussia, Lansdale, Blue Bell, Pottstown, Philadelphia, and the surrounding counties, which means evidence can be in hand the same day rather than in transit.

Remote collection and evidence intake coordination are available nationwide when a matter requires it.

Start a matter

Whether you have a device in hand, a preservation obligation, or a report from the other side that needs a second look, the first conversation is free and takes about thirty minutes.